Falhas do tipo CWE-863

3.050 resultados

Falha em verificação de autorização

O software realiza uma verificação de autorização, mas a implementação está incorreta ou incompleta, permitindo que um atacante contorne as restrições de acesso pretendidas. O erro típico é lógica falha na verificação (condições mal formuladas, casos não tratados) ou confiança em dados do usuário para validar permissões.

Exemplo

Uma aplicação web valida se o usuário está autenticado, mas esquece de checar se ele tem permissão para acessar o recurso específico. Um atacante muda o ID do objeto na URL e acessa dados de outro usuário porque a aplicação não verifica propriedade ou role antes de retornar o conteúdo.

Como mitigar

Implemente verificações de autorização explícitas em todo ponto de acesso a recurso sensível, verificando não apenas quem é o usuário, mas se ele tem permissão específica para aquela ação. Use um modelo de controle de acesso bem definido (RBAC, ABAC) e teste sistematicamente casos de bypass (usuários não autorizados, escalação de privilégio, alteração de parâmetros).

CVE-2026-77786MEDIUMRank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo AbilityEPSS 0.3%CVE-2026-46635MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)EPSS 0.3%CVE-2026-58425MEDIUMOAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)EPSS 0.3%CVE-2026-63309MEDIUMSurrealDB < 3.1.5 Information Disclosure via ORDER BYEPSS 0.3%CVE-2026-70657MEDIUMCopyparty: file/dirkey confusionEPSS 0.3%CVE-2026-55472MEDIUMSnipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary ValidationEPSS 0.3%CVE-2023-26246HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, wEPSS 0.3%CVE-2023-26245HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, wEPSS 0.3%CVE-2026-86490MEDIUMIn JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpointEPSS 0.3%CVE-2025-30744HIGHVulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versiEPSS 0.3%CVE-2024-49808MEDIUMIBM Sterling Connect:Direct Web Services improper authorizationEPSS 0.3%CVE-2025-30743HIGHVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supporteEPSS 0.3%CVE-2024-36364MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisherEPSS 0.3%CVE-2026-24428HIGHTenda W30E V2 Incorrect Authorization Allows Administrator Password ChangeEPSS 0.3%CVE-2024-36377MEDIUMIn JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissionsEPSS 0.3%CVE-2023-26244HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, EPSS 0.3%CVE-2024-36376MEDIUMIn JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissionsEPSS 0.3%CVE-2025-41030MEDIUMMultiple vulnerabilities in Deporsite by T-INNOVAEPSS 0.3%CVE-2025-41031MEDIUMMultiple vulnerabilities in Deporsite by T-INNOVAEPSS 0.3%CVE-2024-51417MEDIUMAn issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static properties/fields.EPSS 0.3%